Citadel: Cyber threat intelligence assisted defense system for software-defined networks

被引:6
作者
Yurekten, Ozgur [1 ,2 ]
Demirci, Mehmet [1 ]
机构
[1] Gazi Univ, Dept Comp Engn, Ankara, Turkey
[2] TUBITAK BILGEM, Cyber Secur Inst, Ankara, Turkey
关键词
Cyber security; Cyber defense; Cyber threat intelligence; CTI; Software-defined networking; SDN; Network function virtualization; NFV; Service function chaining; SFC; SECURITY;
D O I
10.1016/j.comnet.2021.108013
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Defending networks is becoming more challenging due to the growing number and variety of cyber threats. On the other hand, network security professionals have new technologies and tools at their disposal. This paper focuses on a few of these technologies and investigates new ways to take advantage of them. To this end, we present Citadel, a novel security system utilizing cyber threat intelligence (CTI) to construct automated defense solutions in software-defined networking (SDN) environments. Citadel also incorporates network function virtualization (NFV) and service function chaining (SFC) to achieve flexible, cost-efficient, and proactive network defense. We examine CTI data to extract common attacker models and design security services as virtual network functions chained together using SFC to counter these threats. The modular and extensible nature of Citadel makes it suitable for incremental deployment in networks. Besides, we propose a new CTI data model to use as an extension of the existing CTI models for better compatibility with automated network defense. Extensive evaluations demonstrate that our proposals are applicable and effectively facilitate the management of agile defense in SDN/NFV-enabled networks.
引用
收藏
页数:25
相关论文
共 65 条
  • [1] Deceiving Network Reconnaissance Using SDN-Based Virtual Topologies
    Achleitner, Stefan
    La Porta, Thomas F.
    McDaniel, Patrick
    Sugrim, Shridatt
    Krishnamurthy, Srikanth V.
    Chadha, Ritu
    [J]. IEEE TRANSACTIONS ON NETWORK AND SERVICE MANAGEMENT, 2017, 14 (04): : 1098 - 1112
  • [2] Cyber Deception: Virtual Networks to Defend Insider Reconnaissance
    Achleitner, Stefan
    La Porta, Thomas
    McDaniel, Patrick
    Sugrim, Shridatt
    Krishnamurthy, Srikanth V.
    Chadha, Ritu
    [J]. MIST'16: PROCEEDINGS OF THE INTERNATIONAL WORKSHOP ON MANAGING INSIDER SECURITY THREATS, 2016, : 57 - 68
  • [3] Security in Software Defined Networks: A Survey
    Ahmad, Ijaz
    Namal, Suneth
    Ylianttila, Mika
    Gurtov, Andrei
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2015, 17 (04): : 2317 - 2346
  • [4] Security of Software Defined Networks: A survey
    Alsmadr, Izzat
    Xu, Dianxiang
    [J]. COMPUTERS & SECURITY, 2015, 53 : 79 - 108
  • [5] Automated Cyber Threat Sensing and Responding: Integrating Threat Intelligence into Security-Policy-Controlled Systems
    Amthor, Peter
    Fischer, Daniel
    Kuehnhauser, Winfried E.
    Stelzer, Dirk
    [J]. 14TH INTERNATIONAL CONFERENCE ON AVAILABILITY, RELIABILITY AND SECURITY (ARES 2019), 2019,
  • [6] Ancieta J.R.Q., 2015, 15 BRAZ S INF SYST S, P1
  • [7] [Anonymous], 2014, 002V121 GS NFV, P13
  • [8] [Anonymous], 2015, SERVICE FUNCTION CHA
  • [9] [Anonymous], 2014, 5070IODEF PRFC
  • [10] Appala S., 2015, Proceedings of 2nd ACM Workshop on Information Sharing and Collaborative Security, P61